Repository navigation
Conversation
WorkflowServiceStubsOptions.toString rendered only the five fields declared on the subclass, silently dropping every field inherited from ServiceStubsOptions. Target, TLS settings, timeouts, and headers were absent from the output, which is exactly the connection information wanted when diagnosing a client from logs. OperatorServiceStubsOptions and CloudServiceStubsOptions had no toString at all and fell back to Object.toString, logging as an unreadable identity hash. Extract the field rendering on ServiceStubsOptions into a package-private toStringFields helper and have each subclass inline it alongside its own fields. The helper is package-private because all four classes live in io.temporal.serviceclient, so this adds no public API surface. Also include apiKeyProvided, which already participates in equals and hashCode but was omitted from toString. The API key itself is held by a metadata provider and is still never rendered. Fixes temporalio#2148. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Metadata.toString renders header values in the clear. The previous commit propagated the inherited headers field into WorkflowServiceStubsOptions, OperatorServiceStubsOptions, and CloudServiceStubsOptions, which would have newly exposed any credential supplied through setHeaders, such as a static Authorization header. Render the header names only. This keeps the diagnostic signal that matters when reading the output, whether a header is configured and which ones, without printing what they contain. Also add a regression test for the missing separator before congestionInitialInterval in RpcRetryOptions.toString. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
|
1 similar comment
|
|
|
Thanks for the contribution, note the CLA still must be signed before we can merge this |
|
Closing because the CLA is unsigned so this cannot be merged, please open a new PR if you are willing to sign the CLA at a later date. |
What was changed
ServiceStubsOptions.toStringnow renders its fields through a package-privatetoStringFields()that each subclass inlines alongside its own fields.
WorkflowServiceStubsOptionsrendered only the five fields declared on the subclass, droppingevery inherited one — target, TLS, timeouts, headers.
OperatorServiceStubsOptionsandCloudServiceStubsOptionshad notoStringand logged as anidentity hash.
apiKeyProvided, already inequals/hashCodebut missing fromtoString.io.grpc.Metadata#toStringprints values in the clear, soinheriting the field as-is would have exposed credentials set through
setHeaders.,beforecongestionInitialIntervalinRpcRetryOptions.toString.Why?
This output is what lands in logs when diagnosing a client. Two of the three option types rendered
nothing usable; the third omitted every inherited field.
Breaking changes?
None to public API.
ServiceStubsOptions.toStringnow emitsheaderNames=[...]where it used toemit
headers=with values — deliberate, so the fix does not leak credentials.Server PR
N/A.
Checklist
Closes Better toString representations on service stub options #2148
How was this tested:
Five new tests covering each subclass's
toString, asserting no API key or header value appearsin the output, plus a regression test for the separator.
Any docs updates needed?
No.
🤖 Generated with Claude Code